PT-2015-4011 · Qemu+1 · Libvirt+1

Martin Kletzander

·

Published

2014-12-18

·

Updated

2024-06-15

·

CVE-2014-8131

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions libvirt versions prior to 1.2.11
Description The issue arises from the qemu implementation of virConnectGetAllDomainStats in libvirt, which fails to handle locks correctly when a domain is skipped due to ACL restrictions. This allows remote authenticated users to cause a denial of service, resulting in a deadlock or segmentation fault and crash, by making a request to access domains they do not have privileges to access.
Recommendations For versions prior to 1.2.11, update to version 1.2.11 or later to resolve the issue.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2472
CVE-2014-8131
OPENSUSE-SU-2024:10209-1

Affected Products

Alt Linux
Libvirt